Reversing a 2.4GHz Remote Control
xakcop.com
xakcop.com
I was shocked to see how easy the garage door opened once I'd captured a packet with the RTL SDR (on 433 Mhz) and then replayed it through the Rasperry Pi bit-banging FM hack with a tiny wire on a pin. I looked at the code and converted it to 0s and 1s, only to find out that it was always the same and also that the middle part matched the 8-bit hard-coded on/off switch every garage tends to have to adjust your coding (so your neighbour doesn't open yours).
I then realised it would only take about 256 attempts to open just about any garage door in my neighbourhood (most are bought from one or two vendors). All it takes is a Raspberry PI, a USB power-bank and a script that runs in a loop.
Amazing. Shocking also. But fascinating.
I remember reading a text file back in the early 90s downloaded from a bbs that had plans for a master garage door opener. Seemed like magic.
Samy Kamkar's Rolljam supposedly does well against those, though the owner's fob quits working, so it's not stealthy.
When i first stumbled across https://github.com/jopohl/urh (universal radio hacker) i couldn’t believe my luck.
I’ve done stuff like this manually before (as in just collecting all the bits and then trying to ascribe meaning, e.g. https://github.com/cleanflight/cleanflight/issues/1125#issue... ) but i used URH to reverse my bbq temperature sensors.
I have an alexa skill that shows the last 20 readings for both probes on a graph. It is stupidly over-the-top (a Pi with a cheap sdr dongle listens for packets from the bbq down the garden, it parses out the measurements and fires them into a dynamodb which is absurd but it was quick to do, then the Alexa skill just pulls from there and sends to a chart api that draws my line graphs to show on alex’s screen - totally absurd) but great fun to do.
The OP's toy does not have any state so it is quite easy to reverse engineer. All you need is a simple map from a desired action to electromagnetic signal. I am thinking of reverse engineering the protocol between my customizeable mechanical keyboard and its PC software. As the mechanical keyboard has an internal state, it is much more difficult to reverse engineer.
The only problem I have is that the author knows his stuff so well that he falls short of explaining in enough detail.
But maybe that’s an excercise left to the reader.
A friend of mine was trying something like this recently and couldn't figure out how to isolate the signal from all the noise around him. I was hoping this would explain even a little bit, but unfortunately not.
I wonder if the comms ICs used in the car and controller were originally designed for some far more complex use case involving bi-directional signalling, or status feedback?
But between me not having the know-how and any hacking being potentially threatening her health, I never got around to do it. But it would be nice to send a bolus, because the newer smartphone app can't do that via bluetooth.
If I were designing an artificial electronic pancreas like that, I would be super, super paranoid. It's probably one of the few medical devices that I really think should be a strong user of asymmetric cryptography with a challenge-response-challenge-response protocol and multiple independent sanity-checking validation steps at every opportunity. If it can't deliver the bolus it thinks you need, it should alarm loudly and tell you to manually check. If it has a bit flip in the night and slowly drives 255 units of insulin into your bloodstream at 3 am, you won't wake up.
The diabetes community got started on this before the official manufacturers did. Probably in part because the manufacturers were concerned about being 100% bulletproof whereas (some) people living with diabetes were willing to take a bit more risk. And there's a balance around alarms. Some glucose monitoring tech can be frustrating and lead to "alarm fatigue".
Most of the artificial pancreases I'm aware of mitigate some of the risk by rarely sending large boluses at all. They tend to adjust the background basal rate and only send a bolus when you explicitly tell them you've eaten.
The old Medtronic pumps were hacked years ago and Medtronic responded by making it impossible with newer pumps.
By now there are at least 3 different apps on different platforms and they support a variety of pumps.
My next pump will definitely be one that allows remote control and some sort of looping. Whether that's officially from the manufacturer or not.
If you want to tinker with radio stuff for less money, you could start with a receiver only and try RTL-SDR. RTL-SDR is software-defined radio (=SDR) based on a particular RealTek (=RTL) chip. Suitable devices are as cheap as the right DVB-T USB receiver (check the list in the reddit-wiki for what might work and what might not) but there are more optimized devices for approximately $40 (un)available (because supply chain) - have a look at the rtl-sdr shop for those.
"Hacking My Ceiling Fan's Wireless Remote with a USB TV Tuner", https://www.riveducha.com/decode-wireless-signal-with-usb-tv...
"Abusing RPi GPIO pins as a radio controller", https://www.riveducha.com/raspberry-pi-gpio-send-radio-signa...
Have fun and if dad modding their toys gets your kids interested in hacking/tinkering then all the better.
That's impressive reduce it to some lines of code wow
But it was a good idea to give to me to give my girl her first proper RC car. (got her a paw patrol RC car before, but sigh could only go straight or circle left backwards at the same time, and not easy to hack to make it behave like a normal RC car)